July 24, 2026
Startup School of Hard Knocks
I got into YC by hacking it
Founder says he hacked YC’s scoring tool — and the comments are freaking out
TLDR: A founder says he found a serious flaw in YC’s Startup School scoring tool that could let someone fake application scores, and YC says it patched the issue fast. Commenters are split between praising the catch and panicking that startup applicants may be judged by secret software scans.
A founder’s wild post about “hacking” Y Combinator — the famous startup factory behind Airbnb and Stripe — has turned into two stories at once: a security scare and a full-blown comment-section meltdown. The author says a tool used in YC’s Startup School application process let him poke around, uncover how applicants were being scored, and even find a flaw that could let someone fake those scores. The plot twist? After he went public, YC’s Jared Friedman replied within hours, said it was patched, and invited him to Startup School anyway. Internet movie ending, unlocked.
But the real fireworks were in the reactions. One camp was instantly horrified: “Yikes! I hope this is NOT the future of hiring,” as commenters recoiled at the idea of applicants being asked to run a script that scans their code and sends a report back. Others heard alarm bells over privacy, with one person saying it looked like “a bad news story unfolding in real time.” Another crowd was less panicked and more eye-rolling, basically saying: of course a secret scoring system built around vibes and hidden metrics was going to end weirdly. The harshest dunk compared it to startup brainworms: people chasing mysterious numbers until they lose the plot.
There was also nitpicking drama: did he really “get into YC,” or just into Startup School, which commenters pointed out is very much not the same thing. In other words, the thread had everything: privacy panic, metric conspiracy, title-policing, and a little dark comedy about the future of tech applications.
Key Points
- •The author says Y Combinator’s Startup School application required using Paxel to analyze coding work and upload a report.
- •The article claims Paxel was installed through a one-line cURL script that downloaded and ran a Docker-based Ruby application locally.
- •The author alleges they discovered a vulnerability that allowed arbitrary scores to be forged and pushed to YC’s ranking database due to an unvalidated HMAC.
- •The author cites Paxel’s site as saying more than 1.2 million coders had uploaded reports to YC.
- •According to the article, Jared Friedman responded after the public disclosure, said the issue was patched, and invited the author to Startup School in San Francisco.